{"_id":"mergewarden-mcp","_rev":"6-f43db445fe76ed25efa1e50e6dc83f92","name":"mergewarden-mcp","dist-tags":{"latest":"0.10.4"},"versions":{"0.8.0":{"name":"mergewarden-mcp","version":"0.8.0","keywords":["mcp","model-context-protocol","ai-agents","code-review","pull-request","scope","policy"],"license":"MIT","_id":"mergewarden-mcp@0.8.0","maintainers":[{"name":"jinhyuk9714","email":"jinhyuk9714@gmail.com"}],"homepage":"https://github.com/sjh9714/mergewarden#readme","bugs":{"url":"https://github.com/sjh9714/mergewarden/issues"},"bin":{"mergewarden-mcp":"dist/main.js"},"dist":{"shasum":"d67f93c62514440edbbc74bc979c9f3825ae4d90","tarball":"https://registry.npmjs.org/mergewarden-mcp/-/mergewarden-mcp-0.8.0.tgz","fileCount":4,"integrity":"sha512-nRPZmHjjz4qQR9qV9JpaIC/+URF8brfXCb9K/J2BIhepVnDKn6jwIFo6lSL0LmIDQrsbmtY0AJ3rDA1pN4iUkQ==","signatures":[{"sig":"MEYCIQDytCRUNMI2S9o3b58thndVgSVeVsN2TFdNSfWKhkOpxAIhALPoN78EE80b3Maz7Ttw04QJv/d5WOjxCJ7yKu9c/s3m","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":428891},"type":"module","_from":"file:/tmp/mergewarden-mcp-0.8.0.tgz","engines":{"node":">=20.0.0"},"mcpName":"io.github.sjh9714/mergewarden","scripts":{"lint":"eslint .","test":"vitest run","build":"tsup --config tsup.config.ts","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"jinhyuk9714","email":"jinhyuk9714@gmail.com"},"_resolved":"/tmp/mergewarden-mcp-0.8.0.tgz","_integrity":"sha512-nRPZmHjjz4qQR9qV9JpaIC/+URF8brfXCb9K/J2BIhepVnDKn6jwIFo6lSL0LmIDQrsbmtY0AJ3rDA1pN4iUkQ==","repository":{"url":"git+https://github.com/sjh9714/mergewarden.git","type":"git","directory":"packages/mcp"},"_npmVersion":"10.9.8","description":"MCP server that checks whether a coding agent's changes stayed inside the scope it was given","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3","@modelcontextprotocol/sdk":"^1.30.0"},"_hasShrinkwrap":false,"devDependencies":{"@mergewarden/core":"0.8.0"},"_npmOperationalInternal":{"tmp":"tmp/mergewarden-mcp_0.8.0_1785341620074_0.0018126624333012487","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"mergewarden-mcp","version":"0.9.0","keywords":["mcp","model-context-protocol","ai-agents","code-review","pull-request","scope","policy"],"license":"MIT","_id":"mergewarden-mcp@0.9.0","maintainers":[{"name":"jinhyuk9714","email":"jinhyuk9714@gmail.com"}],"homepage":"https://github.com/sjh9714/mergewarden#readme","bugs":{"url":"https://github.com/sjh9714/mergewarden/issues"},"bin":{"mergewarden-mcp":"dist/main.js"},"dist":{"shasum":"9c2e1a084cc91ea19986ccdf64182f685613e53c","tarball":"https://registry.npmjs.org/mergewarden-mcp/-/mergewarden-mcp-0.9.0.tgz","fileCount":4,"integrity":"sha512-RfUVfe71DOy8hprNDltYKjwGKN63Y7f6Jdb24/1RxE/ZEZ3YZZgMSDGO/A5/zH4Glq0i1fUMUYxo/bUH0H2Jmg==","signatures":[{"sig":"MEUCIAMjpnPFFJZuMB9g9bTOZ1ldFwctZ9WaLOBH1mxFxOg0AiEA33cUb57Hj9Rh5AzZA0+jJBTgVlBOMQSedrbJVmQK6hU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/mergewarden-mcp@0.9.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":429940},"type":"module","_from":"file:/home/runner/work/_temp/mergewarden-mcp-0.9.0.tgz","engines":{"node":">=20.0.0"},"mcpName":"io.github.sjh9714/mergewarden","scripts":{"lint":"eslint .","test":"vitest run","build":"tsup --config tsup.config.ts","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:cb82021a-9312-4ac4-9039-8e884a4e0ac5"}},"_resolved":"/home/runner/work/_temp/mergewarden-mcp-0.9.0.tgz","_integrity":"sha512-RfUVfe71DOy8hprNDltYKjwGKN63Y7f6Jdb24/1RxE/ZEZ3YZZgMSDGO/A5/zH4Glq0i1fUMUYxo/bUH0H2Jmg==","repository":{"url":"git+https://github.com/sjh9714/mergewarden.git","type":"git","directory":"packages/mcp"},"_npmVersion":"11.18.0","description":"MCP server that checks whether a coding agent's changes stayed inside the scope it was given","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3","@modelcontextprotocol/sdk":"^1.30.0"},"_hasShrinkwrap":false,"devDependencies":{"@mergewarden/core":"0.9.0"},"_npmOperationalInternal":{"tmp":"tmp/mergewarden-mcp_0.9.0_1785345441114_0.2751027388250027","host":"s3://npm-registry-packages-npm-production"}},"0.10.1":{"name":"mergewarden-mcp","version":"0.10.1","keywords":["mcp","model-context-protocol","ai-agents","code-review","pull-request","scope","policy"],"license":"MIT","_id":"mergewarden-mcp@0.10.1","maintainers":[{"name":"jinhyuk9714","email":"jinhyuk9714@gmail.com"}],"homepage":"https://github.com/sjh9714/mergewarden#readme","bugs":{"url":"https://github.com/sjh9714/mergewarden/issues"},"bin":{"mergewarden-mcp":"dist/main.js"},"dist":{"shasum":"3c69ca19126df34af6ce12368cfd19eb05754b43","tarball":"https://registry.npmjs.org/mergewarden-mcp/-/mergewarden-mcp-0.10.1.tgz","fileCount":4,"integrity":"sha512-481PN2eYrvXRCBFdbU+NNIT0iOSC0glwLLx3PuSogvPTPZRJ6cden+i48q4U7kYYlNAkD2OR+Dzo+/uEi7DbUg==","signatures":[{"sig":"MEYCIQCCeAg8dB/5/Y0eaC6hGDvScOsZeDNYDKOXlL+w7i0LOwIhAN8QbJKaloa+eCLhZg8XG70tyKDpYbU23dU/iqa7sMcc","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/mergewarden-mcp@0.10.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":443456},"type":"module","_from":"file:/home/runner/work/_temp/mergewarden-mcp-0.10.1.tgz","engines":{"node":">=20.0.0"},"mcpName":"io.github.sjh9714/mergewarden","scripts":{"lint":"eslint .","test":"vitest run","build":"tsup --config tsup.config.ts","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:cb82021a-9312-4ac4-9039-8e884a4e0ac5"}},"_resolved":"/home/runner/work/_temp/mergewarden-mcp-0.10.1.tgz","_integrity":"sha512-481PN2eYrvXRCBFdbU+NNIT0iOSC0glwLLx3PuSogvPTPZRJ6cden+i48q4U7kYYlNAkD2OR+Dzo+/uEi7DbUg==","repository":{"url":"git+https://github.com/sjh9714/mergewarden.git","type":"git","directory":"packages/mcp"},"_npmVersion":"11.18.0","description":"MCP server that checks whether a coding agent's changes stayed inside the scope it was given","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3","@modelcontextprotocol/sdk":"^1.30.0"},"_hasShrinkwrap":false,"devDependencies":{"@mergewarden/core":"0.10.1"},"_npmOperationalInternal":{"tmp":"tmp/mergewarden-mcp_0.10.1_1785992234602_0.8001135787577356","host":"s3://npm-registry-packages-npm-production"}},"0.10.2":{"name":"mergewarden-mcp","version":"0.10.2","keywords":["mcp","model-context-protocol","ai-agents","code-review","pull-request","scope","policy"],"license":"MIT","_id":"mergewarden-mcp@0.10.2","maintainers":[{"name":"jinhyuk9714","email":"jinhyuk9714@gmail.com"}],"homepage":"https://github.com/sjh9714/mergewarden#readme","bugs":{"url":"https://github.com/sjh9714/mergewarden/issues"},"bin":{"mergewarden-mcp":"dist/main.js"},"dist":{"shasum":"7c1a916b46fb713ea95a14b0e995ec6cc1cfc0f4","tarball":"https://registry.npmjs.org/mergewarden-mcp/-/mergewarden-mcp-0.10.2.tgz","fileCount":4,"integrity":"sha512-rWRL/kjh3IVTC/X8Y3MoJ3SsdYXWkks7FJ0MKRh8ce94tctQKdYa1q0Js9EKlInhyPtkGEo3e37Mh+LN4KHVFQ==","signatures":[{"sig":"MEUCICcwlpWzXYqZ1qzrLy5rptdBBhOdNqfKVbAi0IQ3xE2DAiEA9caecflqW0/TLK7ESVs+6VAKizk6+Lstv68U01uZPFM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/mergewarden-mcp@0.10.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":443456},"type":"module","_from":"file:/home/runner/work/_temp/mergewarden-mcp-0.10.2.tgz","engines":{"node":">=20.0.0"},"mcpName":"io.github.sjh9714/mergewarden","scripts":{"lint":"eslint .","test":"vitest run","build":"tsup --config tsup.config.ts","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:cb82021a-9312-4ac4-9039-8e884a4e0ac5"}},"_resolved":"/home/runner/work/_temp/mergewarden-mcp-0.10.2.tgz","_integrity":"sha512-rWRL/kjh3IVTC/X8Y3MoJ3SsdYXWkks7FJ0MKRh8ce94tctQKdYa1q0Js9EKlInhyPtkGEo3e37Mh+LN4KHVFQ==","repository":{"url":"git+https://github.com/sjh9714/mergewarden.git","type":"git","directory":"packages/mcp"},"_npmVersion":"11.18.0","description":"MCP server that checks whether a coding agent's changes stayed inside the scope it was given","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3","@modelcontextprotocol/sdk":"^1.30.0"},"_hasShrinkwrap":false,"devDependencies":{"@mergewarden/core":"0.10.2"},"_npmOperationalInternal":{"tmp":"tmp/mergewarden-mcp_0.10.2_1786004789846_0.037339667999194415","host":"s3://npm-registry-packages-npm-production"}},"0.10.3":{"name":"mergewarden-mcp","version":"0.10.3","keywords":["mcp","model-context-protocol","ai-agents","code-review","pull-request","scope","policy"],"license":"MIT","_id":"mergewarden-mcp@0.10.3","maintainers":[{"name":"jinhyuk9714","email":"jinhyuk9714@gmail.com"}],"homepage":"https://github.com/sjh9714/mergewarden#readme","bugs":{"url":"https://github.com/sjh9714/mergewarden/issues"},"bin":{"mergewarden-mcp":"dist/main.js"},"dist":{"shasum":"58f53d96ed5cda5e015601274fac14ae673dcd01","tarball":"https://registry.npmjs.org/mergewarden-mcp/-/mergewarden-mcp-0.10.3.tgz","fileCount":4,"integrity":"sha512-8IZy6dYHcMPJn4n3MdAsLpxO2CACFNYOBd+wfsqZmM/zOVfTyIMm9yeadzKeoaPzIzTDBkTpXCYYzEMKcR9mig==","signatures":[{"sig":"MEUCIQDNVFph2vN1y11wllpQmDKYU9Qq1vbtIWDIak+Y4pr52gIgWYaeUqXtdA6uzmt7prtDAtOT0qriSOoEOwMH+upIZM0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/mergewarden-mcp@0.10.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":443456},"type":"module","_from":"file:/home/runner/work/_temp/mergewarden-mcp-0.10.3.tgz","engines":{"node":">=20.0.0"},"mcpName":"io.github.sjh9714/mergewarden","scripts":{"lint":"eslint .","test":"vitest run","build":"tsup --config tsup.config.ts","typecheck":"tsc --noEmit -p tsconfig.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:cb82021a-9312-4ac4-9039-8e884a4e0ac5"}},"_resolved":"/home/runner/work/_temp/mergewarden-mcp-0.10.3.tgz","_integrity":"sha512-8IZy6dYHcMPJn4n3MdAsLpxO2CACFNYOBd+wfsqZmM/zOVfTyIMm9yeadzKeoaPzIzTDBkTpXCYYzEMKcR9mig==","repository":{"url":"git+https://github.com/sjh9714/mergewarden.git","type":"git","directory":"packages/mcp"},"_npmVersion":"11.18.0","description":"MCP server that checks whether a coding agent's changes stayed inside the scope it was given","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3","@modelcontextprotocol/sdk":"^1.30.0"},"_hasShrinkwrap":false,"devDependencies":{"@mergewarden/core":"0.10.3"},"_npmOperationalInternal":{"tmp":"tmp/mergewarden-mcp_0.10.3_1786009940395_0.6294061577513017","host":"s3://npm-registry-packages-npm-production"}},"0.10.4":{"name":"mergewarden-mcp","version":"0.10.4","description":"MCP server that checks whether a coding agent's changes stayed inside the scope it was given","license":"MIT","type":"module","bin":{"mergewarden-mcp":"dist/main.js"},"dependencies":{"@modelcontextprotocol/sdk":"^1.30.0","zod":"^4.4.3"},"devDependencies":{"@mergewarden/core":"0.10.4"},"engines":{"node":">=20.0.0"},"mcpName":"io.github.sjh9714/mergewarden","repository":{"type":"git","url":"git+https://github.com/sjh9714/mergewarden.git","directory":"packages/mcp"},"keywords":["mcp","model-context-protocol","ai-agents","code-review","pull-request","scope","policy"],"scripts":{"build":"tsup --config tsup.config.ts","test":"vitest run","typecheck":"tsc --noEmit -p tsconfig.json","lint":"eslint ."},"_id":"mergewarden-mcp@0.10.4","bugs":{"url":"https://github.com/sjh9714/mergewarden/issues"},"homepage":"https://github.com/sjh9714/mergewarden#readme","_integrity":"sha512-v0hI4H9LmMoTuiW1u6Pw2Lkrz93BGsfjghNgRzRgxgJDsDGFgeFIKvrE4/6lCyjWtANXakUutjs8o7UVkv8Glg==","_resolved":"/home/runner/work/_temp/mergewarden-mcp-0.10.4.tgz","_from":"file:/home/runner/work/_temp/mergewarden-mcp-0.10.4.tgz","_nodeVersion":"22.23.2","_npmVersion":"11.18.0","dist":{"integrity":"sha512-v0hI4H9LmMoTuiW1u6Pw2Lkrz93BGsfjghNgRzRgxgJDsDGFgeFIKvrE4/6lCyjWtANXakUutjs8o7UVkv8Glg==","shasum":"a397b422dd24612169db212f9668fda8f668a947","tarball":"https://registry.npmjs.org/mergewarden-mcp/-/mergewarden-mcp-0.10.4.tgz","fileCount":4,"unpackedSize":443456,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/mergewarden-mcp@0.10.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCp0U4l9EVAx1lW/km+IMMMaSmRNdz+yOXY+l4J+T9c1AIgNyetw/9WUQWjY4dXRU7yuy8Qi5R4qM5GLrENKjlRf0g="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:cb82021a-9312-4ac4-9039-8e884a4e0ac5"}},"directories":{},"maintainers":[{"name":"jinhyuk9714","email":"jinhyuk9714@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mergewarden-mcp_0.10.4_1787334459270_0.6331461589381897"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-29T16:13:39.932Z","modified":"2026-08-21T17:47:39.682Z","0.8.0":"2026-07-29T16:13:40.206Z","0.9.0":"2026-07-29T17:17:21.278Z","0.10.1":"2026-08-06T04:57:14.738Z","0.10.2":"2026-08-06T08:26:30.004Z","0.10.3":"2026-08-06T09:52:20.588Z","0.10.4":"2026-08-21T17:47:39.400Z"},"bugs":{"url":"https://github.com/sjh9714/mergewarden/issues"},"license":"MIT","homepage":"https://github.com/sjh9714/mergewarden#readme","keywords":["mcp","model-context-protocol","ai-agents","code-review","pull-request","scope","policy"],"repository":{"type":"git","url":"git+https://github.com/sjh9714/mergewarden.git","directory":"packages/mcp"},"description":"MCP server that checks whether a coding agent's changes stayed inside the scope it was given","maintainers":[{"name":"jinhyuk9714","email":"jinhyuk9714@gmail.com"}],"readme":"# mergewarden-mcp\n\nAn MCP server that answers one question: **did this change stay inside the scope it was given?**\n\nOut-of-scope edits are a documented failure mode of coding agents, and the usual\nadvice is to check by hand — run `git diff --name-only` after a session and see\nwhether anything unexpected shows up. This does that comparison mechanically,\nagainst the paths you actually asked for.\n\n## Install\n\nClaude Code reads `.mcp.json`; other clients use their own MCP config file.\n\n```json\n{\n  \"mcpServers\": {\n    \"mergewarden\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"mergewarden-mcp\"]\n    }\n  }\n}\n```\n\n## The tool\n\n### `check_change_scope`\n\n| Input          |                                                        |\n| -------------- | ------------------------------------------------------ |\n| `allowedPaths` | Globs the change was scoped to, e.g. `[\"src/auth/**\"]` |\n| `changedPaths` | What was actually changed, from `git diff --name-only` |\n| `blockedPaths` | Optional globs the change was told not to touch        |\n| `task`         | Optional one-line description, recorded verbatim       |\n\nIt returns the paths that escaped, any edits to agent-instruction files\n(`AGENTS.md`, `CLAUDE.md`, `.mcp.json` and similar), and a ready-to-paste\ncontract block for the pull request body.\n\n```\nNEEDS REVIEW\n\n2 path(s) outside the declared scope. 1 agent-instruction file(s) changed —\nthese steer every future agent run in this repository.\n\n- ERROR contract/out-of-scope: src/billing/invoice.ts changed outside the allowed contract scope.\n- ERROR agent-control-plane/drift: This file can change how AI agents behave in future PRs.\n```\n\n## What it is and is not\n\n**It runs the same engine as the [MergeWarden GitHub Action](https://github.com/sjh9714/mergewarden), on the same default policy.** A clean\nresult here is the result the gate produces later — not a second opinion that\nhappens to agree.\n\n**It is deterministic and offline.** No network, no token, no model call. The\nsame inputs always produce the same findings.\n\n**It only checks what a path list can support**: contract scope, blocked paths,\nand agent-control-plane drift. Workflow permission changes, dependency lifecycle\nscripts and prompt-injection checks need file contents, so they are not here —\nrun `npx mergewarden scan owner/repo#123` once the pull request exists.\n\n**It does not judge the change.** Whether the code is correct is not a question\na path comparison can answer, and nothing here pretends otherwise.\n\n## Why the contract block\n\nThe scan study behind this project found **0 of 2,204** merged agent pull\nrequests declared what they intended to change. The intent existed — the agent\nwas told what to do — but nothing carried it into the pull request where a\nreviewer could check against it.\n\nThat is the gap this closes. The scope is stated while it is still known, and\nthe block it emits is the same one `contract/out-of-scope` parses back out later.\n\n## Registry\n\nListed as **`io.github.sjh9714/mergewarden`** in the\n[official MCP registry](https://registry.modelcontextprotocol.io/v0/servers?search=mergewarden).\n\n## Publishing\n\n`server.json` is the MCP registry manifest. Two constraints worth knowing before\nediting it:\n\n- Its `name` must stay identical to `mcpName` in `package.json`. The registry\n  verifies npm ownership by comparing them, and a mismatch only surfaces at\n  registry-publish time, after the npm release is already out. A test enforces\n  the match.\n- `description` is capped at **100 characters** by the registry. Nothing local\n  catches that; `mcp-publisher validate` does, so run it before publishing.\n\nPublishing is `mcp-publisher login github` (device flow) then\n`mcp-publisher publish`, using the official binary from the\n[registry releases](https://github.com/modelcontextprotocol/registry/releases) —\nthe `mcp-publisher` package on npm is an unrelated project with the same name.\n\nMIT. Part of [MergeWarden](https://github.com/sjh9714/mergewarden).\n","readmeFilename":"README.md"}